Skip to main content
Category: Audit & Attestation

Gap Assessment

Also known as: Gap Analysis
Simply put

A gap assessment is a structured review that compares what an organization is currently doing against a desired standard, framework, or target state to identify where it falls short. It highlights the specific differences, or 'gaps,' between current practices and where the organization wants or needs to be. The results typically inform a plan for closing those gaps, though the assessment itself identifies the differences rather than guaranteeing they will be remediated.

Formal definition

A gap assessment evaluates the difference between an organization's current practices, processes, or performance and a defined governance, risk, and compliance standard or desired future state. It is commonly used to measure alignment against frameworks such as NIST CSF, ISO 27001, SOC 2, or similar benchmarks, producing a prioritized inventory of deficiencies to support readiness planning. Some practitioners distinguish a gap assessment, which defines what the performance gaps are, from a gap analysis, which examines why the gaps exist and what can be done to close them, though the terms are frequently used interchangeably in practice. Findings depend heavily on the accuracy of the defined target state, the scope agreed with the client, and access to relevant stakeholders and evidence; a gap assessment supports compliance readiness but does not by itself constitute certification, attestation, or remediation.

Why it matters

For organizations pursuing compliance readiness or maturing their security program, a gap assessment provides an evidence-based starting point rather than a guess about where they stand. Without a clear comparison against a defined target such as NIST CSF, ISO 27001, or SOC 2, leaders often overestimate their readiness or invest in controls that do not address their most material deficiencies. A gap assessment surfaces the specific differences between current practice and the desired standard, allowing security and business leaders to prioritize work and allocate resources deliberately.

The value of a gap assessment depends heavily on the accuracy of the defined target state, the scope agreed with the client, and access to relevant stakeholders and evidence. A poorly scoped assessment, or one conducted without cooperation from the people who own the underlying processes, can produce misleading findings. It is also important to keep expectations calibrated: a gap assessment identifies differences and supports readiness planning, but it does not by itself remediate those gaps, nor does it constitute certification or attestation. Treating the assessment output as proof of compliance is a common and consequential mistake.

In many engagements, a virtual or fractional CISO uses a gap assessment as a governance and risk instrument, not merely a technical checklist. The findings translate deficiencies into a prioritized plan and inform decisions that remain the accountability of the client organization and its officers. Understanding gaps early tends to reduce downstream cost and rework, but the assessment is only the first step in a longer program of closing those gaps.

Who it's relevant to

Organizations pursuing compliance readiness
Companies preparing for frameworks or attestations such as ISO 27001 or SOC 2 use gap assessments to understand how far current practices fall short of the applicable requirements before committing to a formal audit or certification path. The assessment supports readiness planning but does not itself constitute certification or attestation, so it is best treated as an early diagnostic rather than proof of compliance.
Virtual and fractional CISOs
A vCISO or fractional CISO commonly conducts or oversees a gap assessment as part of program development and governance work, using it to prioritize deficiencies and shape a remediation roadmap. They advise and direct based on the findings, but legal and organizational accountability for acting on the results typically remains with the client organization and its officers.
Security and risk leaders driving prioritization
Internal leaders responsible for governance, risk, and compliance use gap assessments to move from assumptions about their posture to an evidence-based, prioritized view of where the organization falls short. This helps direct limited resources toward the most material deficiencies rather than spreading effort evenly across controls.
Executives and buyers scoping engagements
Decision-makers evaluating security leadership services benefit from understanding that the value of a gap assessment depends on a clearly defined target state, an agreed scope, and cooperation from stakeholders who own the underlying processes. Setting realistic expectations up front, including that the assessment identifies rather than closes gaps, improves the usefulness of the engagement.

Inside Gap Assessment

Scope Definition
A statement of which frameworks, regulations, business units, systems, or control domains the assessment will evaluate against, such as NIST CSF, ISO 27001, SOC 2, HIPAA, PCI DSS, or CMMC. The chosen reference standard determines what constitutes a gap and what is out of scope.
Current State Analysis
An evidence-based review of existing controls, policies, processes, and practices, typically gathered through interviews, documentation review, and stakeholder input rather than hands-on technical testing unless separately contracted.
Target State Reference
The desired posture defined by the selected framework, regulatory obligation, or organizational risk appetite against which the current state is compared.
Gap Identification
Documentation of differences between the current state and the target state, describing where controls are missing, partially implemented, or insufficiently governed.
Risk-Informed Prioritization
An ordering of identified gaps by business risk, likelihood, and potential impact, which a virtual CISO often uses to advise leadership on sequencing rather than treating all gaps as equal.
Remediation Recommendations
Advisory guidance on how gaps might be addressed, including governance, process, and program changes. In a typical vCISO engagement this is direction and strategy rather than hands-on remediation execution.
Findings Report and Roadmap
A deliverable summarizing gaps, associated risks, and a proposed sequence of actions, often feeding into a longer-term security program plan.

Common questions

Answers to the questions practitioners most commonly ask about Gap Assessment.

Is a gap assessment the same as an audit or a certification?
No. A gap assessment is an informal, point-in-time evaluation that compares an organization's current security practices against a chosen framework or standard to identify where controls are missing or immature. It is typically a readiness activity, not a formal audit and not a certification. An audit is generally conducted by an independent party against defined criteria and may carry formal reporting obligations, while certification is issued by an accredited body after a formal assessment. A gap assessment supports readiness for those later processes but does not assert compliance or grant any certification. Buyers should not treat a completed gap assessment as evidence of achieving ISO 27001, SOC 2, or similar outcomes.
Does completing a gap assessment mean the organization is now compliant or secure?
Not on its own. A gap assessment identifies where practices fall short of a target framework; it does not close those gaps. Compliance and improved security posture depend on the remediation work that follows, which often takes time and requires organizational cooperation, resource allocation, and sustained effort. The assessment produces findings and, in many engagements, prioritized recommendations, but the value is only realized when the client acts on them. Treating the report itself as an endpoint is a common mistake.
Which framework should a gap assessment be measured against?
The choice typically depends on the organization's regulatory obligations, customer requirements, industry, and risk profile. Common reference points include NIST CSF, ISO 27001, SOC 2 criteria, HIPAA, PCI DSS, or CMMC, each serving different purposes. A virtual CISO often helps select an appropriate framework based on business drivers rather than defaulting to the most rigorous option. In some engagements more than one framework is relevant, and scope should be defined clearly before the assessment begins to avoid ambiguity in the findings.
What does a virtual CISO typically do during a gap assessment, and what is out of scope?
A virtual CISO generally provides the strategy, governance, and risk-oriented interpretation of the assessment: framing scope, interviewing stakeholders, reviewing documentation and policies, evaluating control maturity, and translating findings into business risk and prioritized recommendations. Hands-on operational tasks such as configuring tools, running technical scans, administering systems, or performing deep penetration testing are typically out of scope unless explicitly contracted, and are sometimes delivered by other specialists. The vCISO advises and directs, while accountability for acting on findings and for security decisions usually remains with the client organization and its officers.
What inputs and cooperation does a gap assessment require from the client?
The quality of a gap assessment often depends heavily on client access and cooperation. This typically includes access to relevant stakeholders across security, IT, and business functions; existing policies, procedures, and documentation; and honest visibility into how controls actually operate rather than how they are intended to. Where organizational maturity is low or documentation is limited, findings may rely more on interviews and observation. Limited access or reluctance to share information generally reduces accuracy and can leave gaps undetected.
How is a gap assessment typically translated into next steps?
In many engagements the findings are organized into a prioritized set of recommendations or a remediation roadmap that reflects business risk, effort, and dependencies rather than simply listing every deficiency. A virtual CISO often helps sequence remediation so that higher-risk or foundational items are addressed first, and may support tracking progress over time. The specific format, prioritization approach, and level of follow-on support may vary by provider and by what the engagement contract defines. Without a defined plan and owner for remediation, findings tend to go unaddressed.

Common misconceptions

A gap assessment certifies or guarantees compliance with a framework such as ISO 27001, SOC 2, or PCI DSS.
A gap assessment supports readiness by identifying where an organization diverges from a standard; it does not confer certification or attestation. Certification and audit are separate processes performed by qualified auditors or certifying bodies, and closing identified gaps remains the client organization's responsibility.
A gap assessment includes hands-on technical testing like penetration testing or vulnerability scanning.
A gap assessment, particularly when delivered by a virtual CISO, is typically a governance and control-maturity review based on interviews and documentation. Technical testing is a distinct activity and is generally out of scope unless explicitly contracted.
Completing a gap assessment means the organization's security decisions and their accountability transfer to the virtual CISO.
The vCISO advises and directs, but legal and organizational accountability for acting on the findings and for security outcomes usually remains with the client organization and its officers unless a contract specifies otherwise.

Best practices

Agree on the reference framework or regulation and the precise scope before starting, since what counts as a gap depends entirely on the target standard.
Secure access to the right stakeholders and documentation early, as the quality of a gap assessment depends heavily on client cooperation and available evidence.
Prioritize identified gaps by business risk and impact rather than presenting a flat list, so leadership can sequence remediation against limited resources.
Clearly distinguish in the deliverable between readiness support and certification, avoiding language that implies compliance is achieved or guaranteed.
State explicitly what was in and out of scope, including that hands-on testing and remediation execution were excluded unless separately contracted.
Frame findings as advisory input that informs a roadmap, reinforcing that accountability for acting on gaps remains with the client organization.